cbcvebase.

Roundcube Webmail vulnerabilities

104 known vulnerabilities affecting roundcube/webmail.

Total CVEs
104
CISA KEV
11
actively exploited
Public exploits
12
Exploited in wild
12
Severity breakdown
CRITICAL11HIGH24MEDIUM62LOW7

Vulnerabilities

Page 4 of 6
CVE-2026-62641P4MEDIUMCVSS 6.5≥ 1.6.0, < 1.6.17≥ 1.7.0, < 1.7.22026-07-14
CVE-2026-62641 [MEDIUM] CWE-770 CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
nvd
CVE-2026-35544P4MEDIUMCVSS 5.3≤ 1.5.13≥ 1.6.0, ≤ 1.6.13+2 more2026-04-03
CVE-2026-35544 [MEDIUM] CWE-669 CVE-2026-35544: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
nvd
CVE-2015-8864P4MEDIUMCVSS 6.1≤ 1.0.8v1.1+1 more2017-04-13
CVE-2015-8864 [MEDIUM] CWE-79 CVE-2015-8864: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 al Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
nvd
CVE-2020-16145P4MEDIUMCVSS 6.1fixed in 1.3.15≥ 1.4.0, < 1.4.82020-08-12
CVE-2020-16145 [MEDIUM] CWE-79 CVE-2020-16145: Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
nvd
CVE-2026-35539P4MEDIUMCVSS 6.1fixed in 1.5.14≥ 1.6.0, < 1.6.142026-04-03
CVE-2026-35539 [MEDIUM] CWE-79 CVE-2026-35539: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insuffi An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
nvd
CVE-2026-26079P4MEDIUMCVSS 4.7fixed in 1.5.13≥ 1.6.0, < 1.6.132026-02-11
CVE-2026-26079 [MEDIUM] CWE-829 CVE-2026-26079: Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
nvd
CVE-2016-4068P4MEDIUMCVSS 6.1≤ 1.0.8v1.1+1 more2017-04-13
CVE-2016-4068 [MEDIUM] CVE-2016-4068: Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 al Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
nvd
CVE-2020-15562P4MEDIUMCVSS 6.1fixed in 1.2.11≥ 1.3.0, < 1.3.14+1 more2020-07-06
CVE-2020-15562 [MEDIUM] CWE-79 CVE-2020-15562: An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1. An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists.
nvd
CVE-2024-37384P4MEDIUMCVSS 6.1fixed in 1.5.7≥ 1.6.0, < 1.6.72024-06-07
CVE-2024-37384 [MEDIUM] CWE-79 CVE-2024-37384: Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferen Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
nvd
CVE-2026-74999P4MEDIUMCVSS 5.4≥ 1.6.0, < 1.6.18≥ 1.7.0, < 1.7.32026-08-17
CVE-2026-74999 [MEDIUM] CWE-79 CVE-2026-74999: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subj In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
nvd
CVE-2009-4077P4MEDIUMCVSS 6.8≤ 0.2.2v0.1+3 more2009-11-25
CVE-2009-4077 [MEDIUM] CVE-2009-4077: Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that send arbitrary emails via unspecified vectors, a different vulnerability than CVE-2009-4076.
nvd
CVE-2023-47272P4MEDIUMCVSS 6.1≥ 1.5.0, < 1.5.6≥ 1.6.0, < 1.6.52023-11-06
CVE-2023-47272 [MEDIUM] CWE-79 CVE-2023-47272: Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposi Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
nvd
CVE-2009-4076P4MEDIUMCVSS 6.8≤ 0.2.2v0.1+3 more2009-11-25
CVE-2009-4076 [MEDIUM] CWE-352 CVE-2009-4076: Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that modify user information via unspecified vectors, a different vulnerability than CVE-2009-4077.
nvd
CVE-2020-12625P4MEDIUMCVSS 6.1fixed in 1.4.42020-05-04
CVE-2020-12625 [MEDIUM] CWE-79 CVE-2020-12625: An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vul An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.
nvd
CVE-2015-5381P4MEDIUMCVSS 6.1v1.12017-05-23
CVE-2015-5381 [MEDIUM] CWE-79 CVE-2015-5381: Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x be Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.
nvd
CVE-2026-75010P4MEDIUMCVSS 4.3≥ 1.6.0, < 1.6.18≥ 1.7.0, < 1.7.32026-08-17
CVE-2026-75010 [MEDIUM] CWE-669 CVE-2026-75010: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
nvd
CVE-2021-44025P4MEDIUMCVSS 6.1fixed in 1.3.17≥ 1.4.0, < 1.4.122021-11-19
CVE-2021-44025 [MEDIUM] CWE-79 CVE-2021-44025: Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
nvd
CVE-2020-13964P4MEDIUMCVSS 6.1fixed in 1.3.12≥ 1.4.0, < 1.4.52020-06-09
CVE-2020-13964 [MEDIUM] CWE-79 CVE-2020-13964: An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_ou An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.
nvd
CVE-2011-4078P4MEDIUMCVSS 5.0≤ 0.5.4v0.1+12 more2011-11-03
CVE-2011-4078 [MEDIUM] CVE-2011-4078: include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows r include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.
nvd
CVE-2021-26925P4MEDIUMCVSS 5.4fixed in 1.4.112021-02-09
CVE-2021-26925 [MEDIUM] CWE-79 CVE-2021-26925: Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during H Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
nvd
Roundcube Webmail vulnerabilities | cvebase